PCAccelerateProUpdater.exe

RPCAcceleratePro

Installer Technology Co.

The executable PCAccelerateProUpdater.exe, “RPCAcceleratePro Updater Component” has been detected as malware by 1 anti-virus scanner. While running, it connects to the Internet address mirror-vip.cs.utah.edu on port 80 using the HTTP protocol.
Publisher:
Installer Technology Co.  (signed and verified)

Product:
RPCAcceleratePro

Description:
RPCAcceleratePro Updater Component

Version:
1.0.0.1

MD5:
25427da223658d886ec578a56cf595a3

SHA-1:
4647c09724101c53812e7951b5d3e9a12f311059

SHA-256:
07207e6dc867a076457c3e0df6219bac2571b2ea5b269205c2f0ca57ced16b79

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/24/2024 10:32:35 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.2.11.6

File size:
83.3 KB (85,328 bytes)

Product version:
1.0.0.1

Copyright:
Copyright Installer Technology © 2015

Original file name:
PCAccelerateProUpdater.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\pcacceleratepro\pcaccelerateproupdater.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
9/27/2016 8:00:00 PM

Valid to:
9/28/2017 7:59:59 PM

Subject:
CN=Installer Technology Co., O=Installer Technology Co., STREET=407 lincoln road, L=miami beach, S=florida, PostalCode=33139, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1B58BBA81BB22C023967D6D579B294FC

File PE Metadata
Compilation timestamp:
2/8/2017 6:53:42 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

Entry address:
0x9B2F

Entry point:
E8, BD, 01, 00, 00, E9, 91, FE, FF, FF, CC, FF, 25, 00, B1, 40, 00, FF, 25, FC, B0, 40, 00, FF, 25, F8, B0, 40, 00, 55, 8B, EC, 8B, 45, 08, 8B, 00, 81, 38, 63, 73, 6D, E0, 75, 25, 83, 78, 10, 03, 75, 1F, 8B, 40, 14, 3D, 20, 05, 93, 19, 74, 1B, 3D, 21, 05, 93, 19, 74, 14, 3D, 22, 05, 93, 19, 74, 0D, 3D, 00, 40, 99, 01, 74, 06, 33, C0, 5D, C2, 04, 00, E8, F0, 03, 00, 00, CC, 68, 4C, 9B, 40, 00, E8, EB, 03, 00, 00, 59, 33, C0, C3, CC, FF, 25, F0, B0, 40, 00, FF, 25, EC, B0, 40, 00, CC, CC, CC, CC, CC, CC, CC...
 
[+]

Entropy:
6.6419

Code size:
36.5 KB (37,376 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to clamav.i-pex.de  (212.227.138.145:80)

TCP (HTTP):
Connects to mirror-vip.cs.utah.edu  (155.98.64.87:80)

TCP (HTTP):
Connects to ftp.nara.wide.ad.jp  (203.178.137.175:80)

Remove PCAccelerateProUpdater.exe - Powered by Reason Core Security